WAZUH Alert
Shellshock attack detected
| Agent | (009) - xxxxx |
| Location | /var/log/nginx/access.log |
| Rule ID | 31169 (Level 15) |
| Log x.x.x.x | - - [06/Jul/2022:01:00:13 -0700] "GET /xampp/cgi.cgi HTTP/1.1" 200 778 "-" "() { ; } >[\((\)())] { echo Content-Type: text/plain ; echo ; echo \x22bash_cve_2014_6278 Output : $((91+8))\x22; }" "-" |
--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh mailing list" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/t-epCxHOtnk/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/1da44994-0c19-4379-bfdd-c22dc8832805n%40googlegroups.com.
Shellshock attack detected
(009) - server01
Location/var/log/nginx/access.log
Rule ID31168 (Level 15)
Log10.20.30.40 - - [13/Jul/2022:01:01:15 -0700] "GET /cgi-bin/clwarn.cgi HTTP/1.1" 200 778 "-" "() { ignored; }; echo Content-Type: text/plain ; echo ; echo \x22bash_cve_2014_6271_rce Output : $((8+30))\x22" "-"
Thanks,
A.Sekhar
CVE-2015-20107 affects libpython3.6-minimal
Agent
(036) - system1
Location
vulnerability-detector
Rule ID
23506 (Level 13)
Log
CVE-2015-20107 affects libpython3.6-stdlib
Agent
(036) - system1
Location
vulnerability-detector
Rule ID
23506 (Level 13)
Log
CVE-2015-20107 affects python3.6
Agent
(036) - system1
Location
vulnerability-detector
Rule ID
23506 (Level 13)
Log
CVE-2015-20107 affects python3.6-minimal
Agent
(036) - system1
Location
vulnerability-detector
Rule ID
23506 (Level 13)
Log
CVE-2015-20107 affects python3.6-minimal
| Agent | (036) - system1 |
| Location | vulnerability-detector |
| Rule ID | 23506 (Level 13) |
| Log |
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/7de1c5ab-413e-4ce0-a72c-8ad6dca6f437n%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/39773b79-0214-4494-ac32-2d44dc53f953n%40googlegroups.com.